LWN.net Logo

clamav: stack overflow

Package(s):clamav CVE #(s):
Created:December 3, 2008 Updated:December 3, 2008
Description:

From the ClamAV bugzilla entry:

There is a recursive stack overflow in clamav 0.93.3 and 0.94 (and probably older versions) in the jpeg parsing code. it scan[]s the jpeg file, and if there is a thumbnail, it'll scan that too. the thumbnail itself is just another jpeg file and the same jpeg scanning function gets called without checking any kind of recur[]sing limit. this can eas[i]ly lead to a recurisive stack overflow.

Alerts:
Ubuntu USN-684-1 2008-12-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds